Title:System Language Discovery via Reg.Exe Status:experimental Description:Detects the usage of Reg.Exe to query system language settings.
Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions,
or avoid targeting certain locales to evade detection.
References: -https://scythe.io/threat-thursday/threatthursday-darkside-ransomware Author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber) Date: 2026-01-09 modified:None Tags: